An information security manager has received complaints from senior management about the level of security delivered by a third-party service provider. The service provider is a long-standing vendor providing services based on a service agreement that has been renewed regularly without much change over the last four years. Which of the following actions is the FIRST one the information security manager should take in this situation?

🎲 Try a Random Question  |  Total Questions in Quiz: 730  |  🧠 Study this quiz with Flashcards
This question is part of a full practice quiz:
Certified Information Security Manager (CISM) Test Prep Questions — practice the complete quiz, review flashcards, or try a random question.

ISACA CISM Exam syllabus in brief:

Information Security Governance    
A. Enterprise Governance
B. Information Security Strategy

Information Security Risk Management    
A. Information Security Risk Assessment
B. Information Security Risk Response

Information Security Program    
A. Information Security Program Development
B. Information Security Program Management

Incident Management    
A. Incident Management Readiness
B. Incident Management Operations


An information security manager has received complaints from senior management about the level of security delivered by a third-party service provider. The service provider is a long-standing vendor providing services based on a service agreement that has been renewed regularly without much change over the last four years. Which of the following actions is the FIRST one the information security manager should take in this situation?